This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Identification and authentication

Information Security

Identification is the recognition of a subject by a unique attribute. Authentication is the verification of the authenticity of the presented identifier.

What is identification and authentication in simple words

Identification and authentication are two interrelated processes that form the basis of access control to information and physical resources. In simple words, identification is when you introduce yourself to the system, and authentication is when you prove that you are exactly who you claim to be.

Identification, authentication and authorization — three stages of access Access granting process: identification ("Who are you?"), authentication ("Are you who you claim to be?") and authorization ("What are you allowed to do?"). Three authentication factors: knowledge, possession, inherence. Identification and authentication: access process User 👤 Access subject Request Identification "Who are you?" Presenting a login or identifier Authentication "Is it you?" Verifying identity (password, biometrics) Authorization "What are you allowed to do?" Access to resources Three authentication factors 🧠 Knowledge (password, PIN) 📱 Possession (token, SMS code) 👤 Inherence (biometrics: face, fingerprint) Identification → Authentication → Authorization: three stages of the access process
Identification and authentication — term diagram

Imagine that you come to a bank. First, you tell the cashier your name (this is identification). Then you present your passport to prove that you are really the owner of this name (this is authentication). In the digital world, everything happens the same way: you enter a login (identification) and a password (authentication).

These processes are the first line of defense of any information system. Without identification, the system does not know who is addressing it. Without authentication, it cannot be sure that the person addressing it is really who they claim to be. Only after successfully passing both stages does the system authorize the user — it determines which resources and actions are available to them.

It is important to understand that identification and authentication are not the same thing, and they cannot be confused. Identification answers the question "Who are you?", and authentication answers the question "Are you really you?". Together they ensure secure access to systems and data.

Authentication methods

There are three classic authentication factors, and they are divided by the type of information being checked:

  • Knowledge (something you know): Password, PIN code, answer to a secret question. This is the most common but also the least secure method, since a password can be spied on, guessed or stolen.
  • Possession (something you have): A phone for receiving an SMS code, a hardware token, a bank card, a key fob. This method is more secure, since an attacker needs to physically take possession of your device.
  • Attribute (something you are): Biometric characteristics — fingerprint, face, voice, iris. This is the most secure method, since biometrics cannot be forgotten, lost or transferred to another person.

Single-factor authentication uses only one of these methods (for example, only a password). Two-factor (2FA) — two different factors (for example, password + SMS code). Multi-factor (MFA) — three or more factors. The more factors used, the higher the security level.

Biometric authentication is becoming increasingly popular thanks to the development of technologies. It is implemented using the Biomark (fingerprints) and Biovizum (face recognition) products. Biometrics provides a high level of security and convenience, as it does not require remembering passwords or carrying additional devices.

In government systems, ESIA (Unified Identification and Authentication System) is used — this is the Gosuslugi portal, which is integrated with SMEV for interdepartmental interaction. Through ESIA, citizens gain access to hundreds of government services using a single login and password or biometrics.

Application

Identification and authentication are used in a wide variety of areas:

  • Logging into operating systems and corporate networks: Every employee undergoes identification and authentication when logging into their work computer or corporate network.
  • Access to web applications and services: Any website requiring registration uses identification (login) and authentication (password).
  • Access control systems (ACS): At enterprises and secure facilities, employees are identified by passes or biometrics, and then authenticated for passage.
  • Banking systems: When logging into an online bank or mobile application, the client undergoes identification and authentication, often using two-factor authentication.

Designing an authentication system includes choosing methods, protocols and protection tools. Design services help develop an optimal architecture taking into account security requirements, ease of use and integration with existing systems. Read more about approaches in the technologies section.

Frequently asked questions

What is the difference between authentication and identification?

Identification answers the question "Who are you?" — you report your login or number to the system. Authentication proves "You are really you" — you enter a password, an SMS code or scan a fingerprint. Identification is presenting yourself to the system, authentication is confirming authenticity. The Biomark and Biovizum products are used for biometric authentication. The design service will help implement an authentication system.

What is identification in simple words?

Identification is the process of recognizing and assigning a unique name (identifier) to a person or object to distinguish them from all others. In simple words, this is the answer to the question: "Who are you?" In IT, this is entering a login when accessing an account; in everyday life, it is presenting a passport. Authentication follows identification — proof that you are really who you claim to be. The Biomark and Biovizum products provide biometric identification.

What is authentication in simple words?

Authentication is the verification of the authenticity of a user. The system makes sure that you are really you and not someone else. This is similar to a guard checking a passport at the entrance: you state your name (login), and the document proves that you are the owner of this name. The system checks: what you know (password), what you have (SMS code) or who you are (biometrics). The Biomark and Biovizum products provide biometric authentication.

What are the 3 authentication factors?

The three classic authentication factors: knowledge (something you know — password, PIN code); possession (something you have — a phone for SMS codes, a hardware token); attribute (something you are — biometrics: fingerprint, face, voice). Using two or three factors is called multi-factor authentication (MFA). The Biomark and Biovizum products are used for biometric authentication. The design service will help implement MFA.

What are authentication and identification systems?

Authentication and identification systems are complexes of tools for recognizing users and verifying their authenticity. An example is ESIA (Unified Identification and Authentication System) on Gosuslugi. It allows citizens to use one login and password to access government services. In corporate systems, the Biomark and Biovizum products are used. The design service will help implement an identification and authentication system.

Is identification possible without authentication?

Identification without authentication is possible, but it does not provide security. The system will know who you are (by login), but it will not be able to confirm that you are really that person. This is like stating your name but not showing a passport — the system can be fooled. Authentication is necessary for full protection. The Biomark and Biovizum products provide reliable biometric authentication.

What are some examples of identification?

Examples of identification: entering a login when visiting a website, scanning a fingerprint to unlock a phone, presenting a passport at a bank. In psychology, identification is the process of identifying oneself with another person or group. In IT, identification is the first step of access, followed by authentication and authorization. The Biomark and Biovizum products provide biometric identification in corporate systems.

Was this information helpful?

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate identification and authentication into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm